1. General information
This Cookie Policy explains how the ferryconnect.pl website (the “Website”) stores information on your terminal device and accesses information already stored there — in particular through cookies. This Policy covers the Website only; it does not apply to the staff administration panel at admin.ferryconnect.pl.
The controller of personal data processed in connection with your use of the Website is:
AFFINITY POLAND Sp. z o.o. — operator of the FerryConnect service
Registered address: [TO BE COMPLETED: street, postal code, city]
Tax ID (NIP): 5253096837 · Statistical no. (REGON): 545220834 · Company register (KRS): 0001251874
Contact e-mail for data protection and cookie matters: [TO BE COMPLETED]
2. What cookies and similar technologies are
Cookies are small text files that your browser saves on your terminal device (computer, phone, tablet) when you use a website. They typically contain the name of the originating site, a storage period and a unique identifier or stored value.
The law covers not only cookies themselves but any storing of information on, or accessing information already stored in, a terminal device — including browser local storage (localStorage, sessionStorage) and similar mechanisms. The Website application does not use browser local storage to track users.
By storage period we distinguish:
- Session cookies — deleted automatically when you close your browser.
- Persistent cookies — stored for a defined period or until you delete them yourself.
3. Legal basis
Storing information on, and accessing information in, a terminal device is governed by Article 399 of the Act of 12 July 2024 — Electronic Communications Law (Prawo komunikacji elektronicznej, Journal of Laws item 1221), in force since 10 November 2024. It replaced the repealed Article 173 of the Telecommunications Law.
Under Article 399(1), storing information on and accessing a terminal device is, as a rule, permitted after the user has been informed in advance and has given consent.
Under Article 399(3), those requirements do not apply where the storage or access is necessary to transmit a message or to deliver a service provided by electronic means that has been explicitly requested by the user.
Every cookie currently used on the Website falls within the Article 399(3) exemption — each one is necessary for the Website to do what you have asked it to do (sign you in, create and pay for a booking, remember your chosen language and currency, protect the service against abuse). For that reason we do not display a cookie consent banner — asking for consent to cookies that are statutorily exempt would be misleading.
To the extent that information from cookies constitutes personal data, we process it under Article 6(1)(b) GDPR (necessary for the performance of a contract or steps taken prior to entering into one — session handling, the booking process) and Article 6(1)(f) GDPR (the controller's legitimate interest in keeping the Website secure and preventing abuse).
Should we introduce analytics, marketing or profiling tools in the future, we will ask for your prior, freely given consent — obtained before any such file is stored, as easy to refuse as to give, and withdrawable at any time. Until then, no such files are used on the Website.
4. Which cookies we use
4.1. Cookies set by the Website
| Name | Purpose | Type | Storage period |
|---|---|---|---|
sb-<project-ref>-auth-token(also .0, .1 variants) |
Keeps you signed in so you can use the customer panel without logging in again on every page. Set only after you sign in. | Strictly necessary | up to 400 days |
NEXT_LOCALE |
Remembers the language version of the Website you selected (Polish or English) so it does not have to be set again on every page. | Strictly necessary — user preference | browser session |
display_currency |
Remembers the currency prices are shown in. Set only when you change the currency yourself using the switcher on the Website. | Strictly necessary — user preference | 12 months |
4.2. Third-party cookies and mechanisms
The Website relies on third-party providers that keep it running and secure. Those providers may store information on your device or access information already stored there, on the terms set out in their own documentation.
| Provider | Where it appears | Purpose | Provider information |
|---|---|---|---|
| Cloudflare, Inc. (hosting and edge protection) |
Entire Website | Security and availability: distinguishing human from automated traffic and protecting against attacks and abuse. Cloudflare may store files such as __cf_bm or cf_clearance for this purpose. Whether they are used, and for how long, follows from the security configuration and Cloudflare's own documentation. |
Cloudflare cookies |
| Cloudflare Turnstile | Quote request form (/oferty) — only when the mechanism is enabled |
Verifies that the form is being filled in by a person rather than an automated script. It loads only on that page and only when configured, and may read or store information on your device for that purpose. | Cloudflare Privacy Policy |
| Stripe Payments Europe, Ltd. | Booking payment | Payment processing. Payment takes place after you are redirected to checkout.stripe.com. Any cookies are then set by Stripe in its own domain and are governed by Stripe's policy, not by this Policy. |
Stripe Privacy Policy |
| Supabase | Sign-in and customer panel | Database and authentication backend. The session cookies described in section 4.1 are set in the Website's own domain by our application, not by Supabase. | Supabase Privacy Policy |
4.3. What we do not use
On this Website we do not use:
- analytics or statistics cookies (e.g. Google Analytics, Matomo, Hotjar),
- marketing, advertising or remarketing cookies (e.g. Meta Pixel, Google Ads),
- profiling or automated decision-making based on cookies,
- any sharing of cookie data with data brokers or advertising networks.
The typefaces used on the Website are served from our own server — your browser does not contact third-party servers to load them. Port directions are plain links; they open only when you click them and are then governed by the map provider's privacy policy.
4.4. Transfers outside the European Economic Area
Some of the providers listed above are established outside the European Economic Area (EEA) — this applies in particular to Cloudflare, Inc. and Supabase. Using their services may involve transferring data to a third country. Any such transfer takes place on the basis of the safeguards those providers declare — a European Commission adequacy decision or standard contractual clauses. Information on the mechanism applied by a given provider is set out in its own documentation, linked in the table in section 4.2.
Stripe Payments Europe, Ltd. is established in Ireland, and therefore within the EEA.
5. Managing cookies
You can change your cookie settings at any time — define the conditions for storing them, block them, or delete those already stored. Your browser settings are used for this:
You can also browse in private (incognito) mode, in which cookies are removed once you close the browser window.
Consequences of restricting cookies. Because the cookies we use are necessary for the Website to function, blocking or deleting them means that:
- signing in to the customer panel and staying signed in will not be possible,
- the booking and payment process may be interrupted,
- your chosen language and currency will not be remembered and will revert to the defaults,
- submitting the quote request form may be blocked by the anti-abuse mechanism.
6. Your rights
To the extent that we process your personal data, you have the right to:
- access your data and obtain a copy of it (Article 15 GDPR),
- rectification of inaccurate or incomplete data (Article 16 GDPR),
- erasure of your data (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- object to processing based on the controller's legitimate interest (Article 21 GDPR).
To exercise these rights, contact us at the e-mail address given in section 1.
You also have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl).
7. Changes to this Cookie Policy
This Policy may change — in particular when new Website features are introduced, service providers change, or the law changes. The current version is always available at this address, and the date of the last update is shown at the bottom of the page.
8. Contact
For matters concerning cookies and the protection of personal data, contact us at the e-mail address given in section 1 or by post to the registered address of AFFINITY POLAND Sp. z o.o.
Last updated: